CVE-1999-1000 to CVE-1999-1999
137 CVEs with public proof-of-concept exploits.
- CVE-1999-10051 PoCGroupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the…
- CVE-1999-10071 PoCBuffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.
- CVE-1999-10083 PoCsxsoldier program allows local users to gain root access via a long argument.
- CVE-1999-10113 PoCsThe Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods,…
- CVE-1999-10142 PoCsBuffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
- CVE-1999-10151 PoCBuffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service…
- CVE-1999-10161 PoCMicrosoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly…
- CVE-1999-10181 PoCIPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a…
- CVE-1999-10201 PoCThe installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote…
- CVE-1999-10221 PoCserial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program,…
- CVE-1999-10241 PoCip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which…
- CVE-1999-10261 PoCaspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the…
- CVE-1999-10281 PoCSymantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
- CVE-1999-10301 PoCcounter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes…
- CVE-1999-10331 PoCMicrosoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently…
- CVE-1999-10412 PoCsBuffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM…
- CVE-1999-10451 PoCpnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
- CVE-1999-10461 PoCBuffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands,…
- CVE-1999-10481 PoCBuffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large…
- CVE-1999-10501 PoCDirectory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot…
- CVE-1999-10534 PoCsguestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to…
- CVE-1999-10631 PoCCDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.
- CVE-1999-10691 PoCDirectory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot…
- CVE-1999-10811 PoCVulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.
- CVE-1999-10822 PoCsDirectory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified…
- CVE-1999-10832 PoCsDirectory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.
- CVE-1999-10842 PoCsThe "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse…
- CVE-1999-10962 PoCsBuffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.
- CVE-1999-11091 PoCSendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from…
- CVE-1999-11101 PoCWindows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which…
- CVE-1999-11121 PoCBuffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image…
- CVE-1999-11131 PoCBuffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of…
- CVE-1999-11141 PoCBuffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to…
- CVE-1999-11171 PoClquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.
- CVE-1999-11201 PoCnetprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows…
- CVE-1999-11232 PoCsThe installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2)…
- CVE-1999-11301 PoCDefault configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to…
- CVE-1999-11582 PoCsBuffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows…
- CVE-1999-11661 PoCLinux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and…
- CVE-1999-11701 PoCIPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
- CVE-1999-11711 PoCIPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to…
- CVE-1999-11771 PoCDirectory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the…
- CVE-1999-11841 PoCBuffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.
- CVE-1999-11852 PoCsBuffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.
- CVE-1999-11902 PoCsBuffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From"…
- CVE-1999-11913 PoCsBuffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
- CVE-1999-11941 PoCchroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.
- CVE-1999-12082 PoCsBuffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.
- CVE-1999-12091 PoCVulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.
- CVE-1999-12191 PoCVulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges,…
- CVE-1999-12351 PoCInternet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the…
- CVE-1999-12431 PoCSGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.
- CVE-1999-12541 PoCWindows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which…
- CVE-1999-12831 PoCOpera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.
- CVE-1999-12861 PoCaddnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a…
- CVE-1999-13091 PoCSendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
- CVE-1999-13402 PoCsBuffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.
- CVE-1999-13421 PoCICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.
- CVE-1999-13711 PoCBuffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name…
- CVE-1999-13751 PoCFileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name…
- CVE-1999-13841 PoCIndigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via…
- CVE-1999-13851 PoCBuffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
- CVE-1999-13901 PoCsuidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.
- CVE-1999-13941 PoCBSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for…
- CVE-1999-13981 PoCVulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink…
- CVE-1999-13991 PoCspaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental…
- CVE-1999-14002 PoCsThe Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass…
- CVE-1999-14021 PoCThe access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before…
- CVE-1999-14051 PoCsnap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the…
- CVE-1999-14081 PoCVulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect…
- CVE-1999-14091 PoCThe at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to…
- CVE-1999-14101 PoCaddnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the…
- CVE-1999-14121 PoCA possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service…
- CVE-1999-14131 PoCSolaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which…
- CVE-1999-14141 PoCIBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs…
- CVE-1999-14231 PoCping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through…
- CVE-1999-14311 PoCZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as…
- CVE-1999-14321 PoCPower management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed,…
- CVE-1999-14331 PoCHP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the…
- CVE-1999-14341 PoClogin in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from…
- CVE-1999-14361 PoCRay Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-1999-14371 PoCePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the…
- CVE-1999-14391 PoCgcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.
- CVE-1999-14411 PoCLinux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial…
- CVE-1999-14421 PoCBug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence…
- CVE-1999-14481 PoCEudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with…
- CVE-1999-14531 PoCInternet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet…
- CVE-1999-14601 PoCBMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as…
- CVE-1999-14611 PoCinpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program,…
- CVE-1999-14772 PoCsBuffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.
- CVE-1999-14791 PoCThe textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.
- CVE-1999-14812 PoCsSquid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the…
- CVE-1999-14831 PoCBuffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-1999-14841 PoCBuffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the…
- CVE-1999-14851 PoCnsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible…
- CVE-1999-14881 PoCsdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.
- CVE-1999-14892 PoCsBuffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long…
- CVE-1999-14901 PoCxosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.
- CVE-1999-14911 PoCabuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary…
- CVE-1999-14941 PoCcolorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.
- CVE-1999-14972 PoCsIpswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for…
- CVE-1999-14981 PoCSlackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.
- CVE-1999-14991 PoCnamed in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process…
- CVE-1999-15041 PoCStalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.
- CVE-1999-15081 PoCWeb server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling…
- CVE-1999-15091 PoCDirectory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a ..…
- CVE-1999-15104 PoCsBuffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary…
- CVE-1999-15121 PoCThe AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message…
- CVE-1999-15151 PoCA non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender…
- CVE-1999-15181 PoCOperating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory…
- CVE-1999-15191 PoCGene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2)…
- CVE-1999-15201 PoCA configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the…
- CVE-1999-15211 PoCComputalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a…
- CVE-1999-15292 PoCsA buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker…
- CVE-1999-15311 PoCBuffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a…
- CVE-1999-15321 PoCNetscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of…
- CVE-1999-15332 PoCsEicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the…
- CVE-1999-15341 PoCBuffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long…
- CVE-1999-15381 PoCWhen IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local…
- CVE-1999-15391 PoCBuffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a…
- CVE-1999-15431 PoCMacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.
- CVE-1999-15441 PoCBuffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a…
- CVE-1999-15511 PoCBuffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-1999-15531 PoCBuffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.
- CVE-1999-15551 PoCCheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL"…
- CVE-1999-15571 PoCBuffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial…
- CVE-1999-15662 PoCsBuffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default…
- CVE-1999-15691 PoCQuake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood…
- CVE-1999-15701 PoCBuffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.
- CVE-1999-15711 PoCBuffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a…
- CVE-1999-15753 PoCsThe Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image…
- CVE-1999-15761 PoCBuffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to…
- CVE-1999-15771 PoCBuffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute…
- CVE-1999-15781 PoCBuffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows…
- CVE-1999-15871 PoC/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and…
- CVE-1999-15881 PoCBuffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long…
- CVE-1999-15931 PoCWindows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a…